CommVault SystemsCVE-2026-77106
Commvault Cloud: missing authorization
High7.7CVE-2026-77106 · Published Sep 8, 2026 · updated Sep 11, 2026
Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Commvault Cloud Product | >= 11.46.0, <= 11.46.19 | No fix yet |
| >= 11.44.0, <= 11.44.19 | No fix yet | |
| >= 11.40.0, <= 11.40.71 | No fix yet | |
| >= 11.36.0, <= 11.36.122 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More CommVault Systems advisories
All CommVault Systems| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Commvault Cloud: authentication bypass | High8.7 | No fix yet |
| Sep 8 | Commvault Cloud: path traversal | High8.3 | No fix yet |
| Sep 8 | Commvault Cloud: improper signature check | High8.7 | No fix yet |
| Sep 8 | Commvault Cloud: authentication bypass | Critical9.3 | No fix yet |
| Sep 8 | Commvault Cloud: path traversal | High8.5 | No fix yet |
| Sep 8 | Commvault Cloud: unsafe deserialization | High7.3 | No fix yet |